5.3
CVE-2025-10731 - ReviewX โ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema โฆ
The ReviewX โ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes it possible for unauthentiโฆ
5.3
CVE-2026-4574 - SourceCodester Simple E-learning System User Profile Update sql injection
A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument firstName results in sql injection. It is possible to launch the attack remotely. The exploit is now puโฆ
5.3
CVE-2026-4573 - SourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection
A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET Parameter Handler. The manipulation of the argument post_id leads to sql injection. It is possible toโฆ
5.1
CVE-2026-4603 - jsrsasign: jsrsasign: Cryptographic operations impacted by division by zero via malicious JSON Web โฆ
Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the BigInteger.modPowInt reduction logic in ext/jsbn.js. An attacker can force RSA public-key operations (e.g., verify and encryption) to collapse to detโฆ
9.4
CVE-2026-4601 - jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature withoutโฆ
9.3
CVE-2026-4599 - jsrsasign: jsrsasign: Private key recovery via incomplete comparison checks biasing DSA nonces
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect comparโฆ
8.7
CVE-2026-4598 - jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inpโฆ
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., โฆ
8.7
CVE-2026-4602 - jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative expโฆ
9.1
CVE-2026-4600 - jsrsasign: jsrsasign: Cryptographic signature forgery via malicious DSA domain parameters
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certiโฆ
6.5
CVE-2025-10736 - ReviewX โ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema โฆ
The ReviewX โ WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up to, and including, 2.2.10. Thisโฆ